logo

Windows XP ToolBox

ID: ccdbfa9c-6e66-5c33-8e60-9e9871b022a4

STIX ID: report--ccdbfa9c-6e66-5c33-8e60-9e9871b022a4

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-11-15

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave with App‑Bound Encryption bypass via IElevator; Opera/Vivaldi via DPAPI; Firefox via NSS). It performs DLL injection into a headless Chromium process (Early Bird APC) to decrypt app_bound_encrypted_key, parses on‑disk SQLite/JSON stores, includes EDR‑evasion features, outputs structured JSON, and is intended for red‑team assumed‑breach testing but presents a realistic risk of credential theft and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.